Suspicious Rundll32 Execution
This rule detects suspicious execution of rundll32.exe by looking for multiple instances of rundll32.exe executing with command lines containing both '.dll' and '/' characters from the same computer and account. This pattern can indicate an adversary attempting to proxy execution of malicious code via rundll32.exe.
Microsoft Sentinel (KQL)

